Suspicious Google OAuth Token Request for Malicious Identity
Detects OAuth2 JWT bearer-grant token requests to Google's OAuth endpoint using the attacker-controlled service-account identity and Sheets API scope observed in the fake GlobalProtect campaign
Microsoft Sentinel (KQL)

